Exploitdb Exploits

31,332 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108209 EXPLOITDB text
Joomla! Component Appointments for JomSocial 3.8.1 - SQL Injection
by Ihsan Sencan
EIP-2026-109406 EXPLOITDB text
memcache-viewer - Cross-Site Scripting
by HaHwul
EIP-2026-108736 EXPLOITDB text
Joomla! Component JooDatabase 3.1.0 - SQL Injection
by Ihsan Sencan
EIP-2026-108728 EXPLOITDB text
Joomla! Component JO Facebook Gallery 4.5 - SQL Injection
by Ihsan Sencan
EIP-2026-108663 EXPLOITDB text
Joomla! Component GPS Tools 4.0.1 - SQL Injection
by Ihsan Sencan
EIP-2026-108246 EXPLOITDB text
Joomla! Component Community Surveys 4.3 - SQL Injection
by Ihsan Sencan
EIP-2026-108245 EXPLOITDB text
Joomla! Component Community Quiz 4.3.5 - SQL Injection
by Ihsan Sencan
EIP-2026-108244 EXPLOITDB text
Joomla! Component Community Polls 4.5.0 - SQL Injection
by Ihsan Sencan
EIP-2026-108196 EXPLOITDB text
Joomla! Component AJAX Search for K2 2.2 - SQL Injection
by Ihsan Sencan
EIP-2026-108884 EXPLOITDB text
Joomla! Component UserExtranet 1.3.1 - SQL Injection
by Ihsan Sencan
EIP-2026-108876 EXPLOITDB text
Joomla! Component Store for K2 3.8.2 - SQL Injection
by Ihsan Sencan
EIP-2026-108799 EXPLOITDB text
Joomla! Component MultiTier 3.1 - SQL Injection
by Ihsan Sencan
EIP-2026-102511 EXPLOITDB text VERIFIED
NetGain Enterprise Manager 7.2.562 - 'Ping' Command Injection
by MrChaZ
CVE-2017-5359 EXPLOITDB HIGH text
EasyCom SQL iPlug - DoS
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.
by hyp3rlinx
CVSS 7.5
CVE-2017-5358 EXPLOITDB CRITICAL text
EasyCom for PHP 4.0.0.29 - Buffer Overflow
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.
by hyp3rlinx
CVSS 9.8
EIP-2026-108888 EXPLOITDB text
Joomla! Component VehicleManager 3.9 - SQL Injection
by Ihsan Sencan
EIP-2026-108841 EXPLOITDB text
Joomla! Component RealEstateManager 3.9 - SQL Injection
by Ihsan Sencan
EIP-2026-108783 EXPLOITDB text
Joomla! Component MediaLibrary Basic 3.5 - SQL Injection
by Ihsan Sencan
EIP-2026-108615 EXPLOITDB text
Joomla! Component ContentMap 1.3.8 - 'contentid' SQL Injection
by Ihsan Sencan
EIP-2026-108224 EXPLOITDB text
Joomla! Component BookLibrary 3.6.1 - SQL Injection
by Ihsan Sencan
EIP-2026-103326 EXPLOITDB text
Teradici Management Console 2.2.0 - Privilege Escalation
by hantwister
CVE-2017-7852 EXPLOITDB HIGH text
Dlink Dcs-2230l Firmware < 1.03.01 - CSRF
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.
by SlidingWindow
CVSS 8.8
EIP-2026-115750 EXPLOITDB text VERIFIED
Microsoft Office PowerPoint 2010 - MSO/OART Heap Out-of-Bounds Access
by Google Security Research
EIP-2026-115749 EXPLOITDB text VERIFIED
Microsoft Office PowerPoint 2010 - GDI 'GDI32!ConvertDxArray' Insufficient Bounds Check
by Google Security Research
EIP-2026-115748 EXPLOITDB text VERIFIED
Microsoft Office PowerPoint 2010 - 'MSO!Ordinal5429' Missing Length Check Heap Corruption
by Google Security Research